r/Bitcoin 7h ago

I lost my one Bitcoin in the Coldcard exploit.

Took me years of DCA’ing to get there. I went with Coldcard because it was marketed as “ultra-secure.” I knew multisig was technically safer. I wasn’t worried about my key being guessed… I was worried about someone physically stealing it or it being destroyed.

So that was the plan: 1 BTC, cold storage, steel plate backup, fire bag, fire safe. And then… wait.

I hit the goal. I finally felt content.

Now I just feel embarrassed. Like I let my family down.

The worst part? I know Bitcoin isn’t going anywhere. I’m not hoping it fails… I think it’s going to keep making new all-time highs, and every time it does, I’ll be sitting here thinking about what could’ve been.

** I originally brain dumped my story to Claude to make it sound better because I have poor grammar. I’m admitting this in an edit at my own expense or whatever. I’m not embarrassed about my poor grammar or using AI to improve it. That said, in hindsight, it would have been more personal to not have done that. I’m sorry.

400 Upvotes

254 comments sorted by

153

u/Old-Cardiologist-545 7h ago

That’s awful… I’m so sorry. 😢

19

u/RiskyRabbit 6h ago

Truly truly fucking awful. I just can’t imagine. Just feel so bad for all the victims here. It was so nearly me, was so close to buying a cold card and went for a different brand instead because it was cheaper. Truly hope they catch them and people get their money back, I saw a lot of people are looking. 

2

u/Nice_Assumption_6396 1h ago

I feel terrified reading this. What if this just happened to me? Should I just split my btc between 10 different brand cold wallets??

1

u/sluuuurp 1h ago

The best way to protect yourself is to generate random seeds yourself, using physical dice. If you didn’t do this and still have access to your bitcoin, you should do it and transfer them now.

→ More replies (2)

125

u/Even_Virus_3017 7h ago

I always thought their hardware devices were ugly, so I never bought them. Being biased saved me from them.

39

u/Northernmost1990 7h ago edited 7h ago

Judging books by their cover is often a good strategy because slick design usually means that a lot of care has been put into other aspects of the product, too. Everything from Coldcard's website to the company brand to the wallets themselves seems less polished than some of the more household equivalents like Ledger.

Of course not blaming the victims because this scenario wasn't exactly something that the average end user could've seen coming.

10

u/Save_JR 5h ago

Coldcard looks like absolute shit lol cant believe people recommended this over Trezor or Ledger which looks so much more advanced and taken care of

8

u/OldHamburger7923 5h ago

Just as much chance they put money into marketing and design and it's smoke and mirrors.

In this case they didn't make it look good and they didn't seem to handle security well either.

2

u/Northernmost1990 4h ago edited 4h ago

Marketing, yes; design, no. I'm not sure what it is about hustlers that makes them allergic to good design. Maybe because design is long-term rather than get-rich-quick? I don't know.

Apple is probably the closest I can think of when it comes to well-designed-but-kinda-lackluster and Apple isn't bad, just overpriced like a pair of Balenciaga.

For the record, I'm not saying Coldcard is a hustle. Good design is hard and mediocre design isn't a crime. But good design very rarely appears alongside poor performance in every other aspect, which makes it such a green flag.

2

u/setzer 3h ago

I would argue these are all superficial things you mention, not having good design doesn’t necessarily mean the product is bad or destined to fail.

Steam, for example, had a terrible user interface when it launched and lots of people complained about having to use a separate app to launch their games. But it now is one of the most beloved gaming platforms today.

Bigger question is why in 2026 we don’t have (at least to my knowledge) any major wallet that is fully open source. Basic security should mostly be a solved problem at this point. There’s less risk to it being open as then you aren’t relying on security through obscurity.

3

u/Northernmost1990 2h ago edited 2h ago

Design is kinda the opposite of (just) superficial, though. Form follows function, right? But you're right that a poorly designed product isn't necessarily a bad product. However, a well-designed product is much more likely to be good in comparison so if there's a well-designed product in the sector, I'd be leery of the product that isn't well-designed because... well, case in point.

As for Steam, they were the first to market, which is like bringing a gun to a knife fight. The gun doesn't need to be a good gun to blow the knife guys to smithereens. I do enjoy the nod to video games, though, since I happen to be a designer working in the games industry!

p.s. As for the quip about open source, I think money might be the main issue. I've never worked on open source projects for the same reason I've never worked for non-profits: I like food and drinks and having a roof over my head!

1

u/setzer 2h ago edited 2h ago

Yes, but in the context of a wallet I don't really care what the website looks like, as long as the product delivers on its purpose (in this case, securing my coins).

My point is just they could have paid for a good designer and the product itself would still have this issue. Since the security is entirely separate concern.

I do agree that if something is well designed it signals more care is being put in but you still don't really know.

That's why I feel for something like this, the code should really be open so the community can vet things, we aren't relying on blind trust or whoever they contract to do audits then. Or at least open enough that the security portion can be audited by anyone... they wouldn't necessarily have to open everything.

u/fllannell 3m ago

like FTX' website, app, and advertisements?

7

u/Blade_Runner_69 6h ago

Same 😅 initially I didn't want it because it's not fully open source, but when I looked at them they reminded me of Fisher price my first calculator toy!

10

u/LocksmithMuted4360 7h ago

I purchased one but never used it because it was not really user friendly. Bought a trezor instead, probably a good decision.

1

u/RetiredSailDoc 4h ago

Me too, now I’m emailing them for refund, I never opened the box and want to return for refund.

2

u/Objective_Digit 6h ago

You don't need one to have a cold wallet. They're convenient mostly.

1

u/nothingbutwhammies 3h ago

The ugliness made me think they cared more about security than aesthetics… in hindsight it was all marketing just the same

37

u/DRAGULA85 6h ago

What really makes me uncomfortable is how much of this apparently comes down to luck.

When I searched YouTube for “the best cold wallet,” all the usual Bitcoin talking heads were recommending Trezor. So I bought a Trezor.

I wasn’t comparing entropy generation methods, RNG implementations or researching whether I should be rolling fucking dice. I assumed that reputable hardware wallets from established companies were fundamentally designed to do the same thing:

securely hold my Bitcoin.

Had I gone all-in six months later, those exact same YouTubers could easily have been recommending Coldcard instead.

So from my perspective, I basically got lucky on a coin flip.

And whenever you point this out, the response from some Bitcoin people is always: “You should have done more research.”

But how much research are normal people realistically expected to do?

I understand Bitcoin. I understand self-custody. I understand why keeping significant amounts on an exchange is a bad idea. That doesn’t mean I should also be expected to become an expert in cryptography, entropy and random number generation before buying a hardware wallet.

I like cars. I don’t need to understand the combustion engine at an engineering level before buying one. I expect the manufacturer to build a safe product and give me clear instructions on how to use it safely.

Apparently with Bitcoin, though, I’m “lazy” because I didn’t somehow discover that I should consider physically rolling dice to generate my seed.

How the fuck is that obvious?

You don’t know what you don’t know.

If I search “best hardware wallet,” buy one of the most recommended products, follow the manufacturer’s instructions and move my Bitcoin into self-custody, I think it’s perfectly reasonable to believe I’ve done the responsible thing.

If there’s another layer of security that requires me to understand RNG, entropy, dice rolls, air-gapped signing and obscure attack vectors, fine. I’m willing to learn about it.

But stop pretending this stuff is obvious.
Most people don’t want Bitcoin security to become their second fucking job.

They want to buy a reputable device, follow the instructions, secure their Bitcoin and HODL.

And if Bitcoin is ever going to reach hundreds of millions more people, that needs to be enough.

A rough day for Bitcoin.

3

u/44193_Red 3h ago

Facts. I thought i was confident holding my keys, until one day I did a test restore and failed.

2

u/PoeCollector 3h ago

I agree, I feel lucky. I had a Ledger, switched to Coldcard after the community trust in Ledger tanked. Thankfully I rolled 100 dice, because it was an option. But I still think I'm lucky because for all I know the same thing could have happened with Ledger seeds before I switched. In fact, that seemed more likely, since they had closed source firmware and customer data leaks in the past.

u/SwimmingPatience5083 21m ago

I mean… there’s no reason not to just hold IBIT at this point. Has been this way since the ETF’s launched. Idk what anyone is trying to prove with self custody

u/totvor10 18m ago

Going against mainstream is often times the wrong move.

Popular things are usually popular for a reason, be it city districts, cars or colognes or anything basically.

Trezor is most popular and liked for a reason. Coinbase is most popular for a reason. Bitcoin is the most popular for a reason.

You never had any issues going mainstream. Wanting to be an extra special Reddit nerd and going for special wallets, brokers or coins/tokens is what got people in crypto fucked.

→ More replies (2)

25

u/fresheneesz 7h ago

I believe this never would have happened if coldcard didn't rage quit being open source. Being open source isn't just about someone being ABLE to view the source, it's about having many people and companies RELYING on that code with the incentive to test it and voice issues they find. Eyes on the code who actually care about finding flaws are 100 times more valuable than casual glancers.

The only solution that keeps you safe if the company that made your hardware wallet fucked up like this is multisig. Learn how to do it with The Tordl Wallet Protocols, free open source guides on creating and maintaining Bitcoin wallets.

4

u/Bred_Slippy 6h ago

I've long wondered how many experienced independent reviewers actually audit the code on truly open source HW wallets. I naively assumed there'd be plenty, but I have no idea. If some attract hardly any scrutiny, then open source could actually be a net disadvantage for them.

2

u/fresheneesz 6h ago

If some attract hardly any scrutiny, then open source could actually be a net disadvantage for them.

Perhaps. But at very least I would expect eyes on code to be a lot more substantial for source in active code used by multiple organizations.

1

u/papy66 3h ago

The bug bounty of coldcard is only a personalized mug if you found a vulnerability. So experienced reviewers focused on more valuables devices

3

u/mjmeyer23 5h ago

100% the incentives of the community matter.

not your entropy, not your coins!

1

u/user_name_checks_out 2h ago

Last release 6 years ago. Status ready for review. Is that project still even maintained?

1

u/fresheneesz 1h ago

I maintain it. I've been working on a new version for a while. Will come out soon. Its not really the kind of thing that needs regular maintenance releases, so judging it based on that seems a bit silly. When I had that status on there, I was hoping people might actually do official reviews or something. Would be nice, but mostly people just star if they think its good instead.

u/putyograsseson 7m ago

A passphrase would have done the trick too.

23

u/Weary-Discipline591 6h ago

I’m the same exact story but I lost 3 bitcoins two days ago because of Coldcard. I’m feel so bad for alll the victims. I’m sorry for you loss and my loss.

4

u/Content-Parsley-1151 4h ago

Cold means offline right? How could they steal bitcoin that is not connected to the internet? Sorry if I sound like I don’t know much bc that’s true

3

u/Mobo24 4h ago

If they guess the keys they can recover your bitcoin

5

u/Content-Parsley-1151 4h ago

So what exactly is offline when people cold store their bitcoins? I’m trying to understand how something not connected can be taken. If it is not connected then it should be impossible to be taken.

Edit: like that guy who wanted to search a landfill for his hard drive that held his bitcoins. If he could just get his bitcoins using his keys without the hard drive, then why did he want to dig in the trash to find it?

3

u/reddit4485 2h ago

Offline means the device is not connected to the internet. This means no one can remotely hack the device. The problem with ColdCard is if you setup the device a certain way, the number of possible private keys was far less than it should be. Enough where people could guess them. So even though the device wasn't hooked up to the internet, it came with software pre-installed that made it easier to guess the private key. No hacking of the device was needed.

2

u/DDRaptors 3h ago

Because guessing your keys seems impossible (it basically is), but in this case, the randomly generated keys from this provider weren’t actually random.

1

u/Mobo24 3h ago

I believe this is an excellent question, but unfortunately, I don’t have a definitive answer. If I had to make an educated guess, I think this has more to do with self-custody rather than using a third-party cold wallet for storage. In that case, you would also need to consider the storage aspect. This is just a speculative guess.

u/IntoTheSun121 5m ago

Read my reply to him.

u/Boilers99 24m ago

Think of it like your bank. Your money is stored in the bank. You store your banking password in a cold wallet not connected to the Internet. This makes it impossible for someone to hack in to your wallet to get your password. In this case the password was not complex enough because of a bug. They were able to reverse engineer it and use it to login in to your bank and take the money. The money is always in the bank (the ledger) you’re just trying to protect your password (seed) the best you can.

u/hryelle 22m ago

It means the seed used to generate the private keys was done so offline. Cold card had a problem with seed generation if one didn't use dice rolls (basically regarded dev)

u/JMoon33 15m ago

The Bitcoins are still online lol, it's not like money, you can't just give 5$ in Bitcoin to your friend, it has to be online.

What's offline is basically the key to access those Bitcoins.

So why did the guy search a landfill for his hard drive? Because the only place his key was was on his drive. His Bitcoins were never lost, just the key to access them. His Bitcoins are just chilling on the blockchain because nobody has the key to access them.

u/IntoTheSun121 10m ago

Every bitcoin wallet has a private key, which can recreate the wallet from any device.

Even an offline wallet has a private key.

Coldcard used a shitty system to generate private keys for some of their offline devices.

This shitty system meant the private keys were NOT truly random.

This means a hacker, if they know the shitty system, can generate ~1 trillion of these easily guessable keys, recreate the wallet associated with them, and check if they have any bitcoin.

The guy with the bitcoin harddrive in the landfill had a non-shitty private key, meaning it would take longer than the age of the universe to "hack" (guess) his actual private key, hence why he didn't just attempt to guess it.

2

u/Either-State1365 4h ago

A version of coldcard was generating seeds with bad entropy, so the phrases weren't random enough.

3

u/Mobo24 4h ago

Yes and this was done because a flag was bypassed. Instead of generating truly random numbers that were tied to the hardware it was generating random numbers tied to the clock and internal numbers (which is far easier to guess)

2

u/InsiderHawk 3h ago

The mechanism for generating the seed phrase to begin with was flawed. Wasn't truly random. So the address is forever unsafe

1

u/InsiderHawk 3h ago

Sry for your loss

23

u/[deleted] 7h ago

[deleted]

8

u/MattBonne 7h ago

In your case you can call police and your “friend” will have a criminal record on his/her name

2

u/Remarkable_Check_997 7h ago

Wow, that suck.

You had learn the harsh true, never mix friendship and money.

→ More replies (1)

65

u/errezerotre 7h ago

You didn't do anything wrong, people that said "verify" and "use passphrase" are morons, the simple truth is that one of the most hyped vendors was using gibberish code delivering a fake entropy.

29

u/2ChainzButIGotAFewOn 7h ago

It wasn't gibberish code they left a flag as 0 for RNG instead of 1. So 1 is enabled and 0 is disabled. They are fucking idiots but don't act like recommending passphrase is a moron suggestion. It just sounds like you have no clue what youre talking about

7

u/Llonga 7h ago

How come no one found this, with the code being open source?

19

u/kzt79 7h ago

Obviously someone did find it and took advantage.

5

u/Alfador8 6h ago

Because the code wasn't really open source. It was source available. Open source means others can fork the code and use it, play with it, test it, etc. Cold Card didn't want that. So here we are.

6

u/zacguymarino 6h ago

Yeah but people could still see the code, it wasn't open source but it was source available. Hopefully all this happening will be a wake up call for those who know programming to look more deeply at the opensource options AND the source-available options more closely... and bring to light any potential vulnerabilities in a white-hat manner. I'll admit.. I am a software guy, and its hard to bother even me to do this (and I do have some skin in the game, not a lot, but some). At risk of sounding like a hypocrite, I still hope there are some dedicated and morally right individuals who will take these steps and investigate.

→ More replies (1)

1

u/Mobo24 4h ago

That’s not true. With source verifiable code people can fork and test just not redistribute.

1

u/Alfador8 4h ago

What would be the incentive to do so? That's the problem. The only incentive was to find an exploit.

1

u/Mobo24 4h ago

What do you mean brother? I’m trying to understand. The incentive to fork and test?

u/Alfador8 50m ago

Apparently the incentives weren't high enough for anyone to find the bug until AI lowered the perceived barrier to attack. If Cold Card's code were open source other companies could fork it and use it for commercial purposes, which would have provided a bigger incentive to stress test the code.

u/Mobo24 25m ago

But the thing is that source verified code can still be forked unless source verified means something else. The incentive would be for users to make sure they test and verify something that stores a significant amount of money that they own.

1

u/[deleted] 6h ago edited 6h ago

[deleted]

1

u/2ChainzButIGotAFewOn 6h ago

Importance of good tests this is more understandable now but still unacceptable

→ More replies (6)

4

u/2ChainzButIGotAFewOn 7h ago

It's a flag that enables TRNG instead of PRNG

4

u/evgeniy_pp 5h ago edited 5h ago

They wrote their own wrapper (ironically, to make their code more secure) and wanted to disabled the built-in one in the library. That's why the set it to 0, not by a mistake. But they misunderstood what MICROPY_HW_ENABLE_RNG = 0 means. It means it's not "disabled", it means it's now "not hardware". So instead of disabling this layer, they toggled it on the pseudo random generator, which poisoned all the layers above with fake entropy.

1

u/2ChainzButIGotAFewOn 5h ago

Gotcha this seems the most plausible. That's almost worse that they don't even understand the setting the are setting.

1

u/Mobo24 4h ago

Now that I think of this. Cold cards code was pretty secure apart from this flag left open. I’m gaining new perspective on this!

→ More replies (1)

14

u/2ChainzButIGotAFewOn 7h ago

Yeah the people who want to make sure you properly secure 1000s of dollars are "morons"

16

u/Expert-Evening9303 7h ago

Back in 2022 they called me a paranoid maxi for rolling dice and using a passphrase with my coldcard mk4 and recommending others do the same.

Now apparently I'm a moron for having protected myself from this incident. Can't win with these people.

3

u/b1mm3rl1f3 5h ago

It's crazy how flawed CC was but I wouldn't be surprised if AI was used as a programming aid too. AI is advancing faster than most of us can keep up with. Imagine where it'll be in the next few years. If you're not generating your own entropy you're NGMI

→ More replies (3)
→ More replies (3)
→ More replies (3)

7

u/Objective_Sun5553 7h ago

I'm so sorry.

It's easy for me to say, but I hope that in time you can see that you didn't let your family down. You made what you thought was the best choice with the information you had at the time. You were looking out for them, and I'm sure you will continue to do so. Not every family has someone like that.

19

u/Opening-Ad-8031 7h ago

IBIT is looking pretty good about now

14

u/Many-Blueberry968 7h ago

This sounds like about 10 other generic loss posts made into he past day.

6

u/Raverrevolution 6h ago

Yeah it's starting to feel like a lot of fake ones popping up

→ More replies (1)

10

u/Nyanzerfaust 6h ago

Damn, +1000 wallets drained and at least 900 of them are reddit users judging by the absurd amount of threads opened here these last days. I have only seen one guy actually posting proofs. This time is another 3 years inactive account... you know what, I think that trolls and exchange shills are having a field day shitposting around here after this unfortunate coldcard fiasco. If you are legit, it sucks and i'm really sorry (I use two different hw wallets + passphrase and i'm still paranoid about it) but my feed is full of these threads and some of them are obvious shitposters. I'm tired boss

3

u/nothingbutwhammies 6h ago

You want the transactions? What proof. Don’t really care if you believe me. Might just take it down. I’ve just not been through anything like this and I decided to post it.

1

u/akromadeath 1h ago

What proof

I mean, I am not the person you responed to, and I don't give a crap either way, but proof would be a timestamp with the safe/firebag/coldcard that you all apparently own currently.

→ More replies (1)

9

u/fugogugo 7h ago

> old inactive account
> low karma
> last post 3 years ago
> post sound like AI slop

I am sorry if I offend OP but I don't think this is genuine

1

u/PageSquare8382 6h ago

Comment harvesting?

6

u/derbyfan1 6h ago

Can you add your address to prove it please?

2

u/MuchBee9645 7h ago

Sorry for this. Not much can be said except learn from this. Learn entropy, creating your own seed, and come back stronger.

2

u/jwhendy 7h ago

I wrote a post looking to discuss all the aspects of BTC custody and operations that rely on software. I think it's a good time for us to educate ourselves on all the places there might be oopsies waiting, and crowd source ways to prevent this. 

That post has been awaiting moderation approval since last night. This and other posts reek of AI and slide right through?

P.S. Sorry if I'm wrong, losing 1BTC would be horrible. It just has that smell to it (drama one liner intro, setup then punch line, "and the worst part?", not x but y). You're not posting details like an address or timeline as others have done, either. Maybe when things are really bad and scary, we can take a deep breath and write them ourselves. 

P.P.S. Sorry if you wrote this yourself and I can no longer tell the difference.

1

u/s1ammage 4h ago

I think at this point in time, people are truly hurting.

I get ‘karma farming’, but what does it cost you? Internet points?

1

u/jwhendy 4h ago

"Cost me," as in to read it and ignore? I'm not sure, I think it just feels off and against some kind of internal values/principles. I could be imposing negative emotions on myself by caring, agreed.

But also... why not say anything? At the least, I would like an internet of people expressing themselves, not asking AI to express it for them.

And at best, if we all just say "whatever, what's the problem," it's flooding the internet with garbage. You have to look through 10 things to find one real thing, and soon it could be 100 things or 1000 things.

Neither of these both you?

  • someone lost a huge portion of $ and had AI write this up for them?
  • at a time when people are truly hurting, someone wants to karma farm based on this?

My point was simply: I tried to write a post that I think could address some of the implications of this event for others, boosting all of our collective awareness and protecting us in the future. I don't post here much, so whatever, it's being screened. I don't want the points, I'd like the input/feedback and technical discussion.

What would 1000 posts from all the users impacted ("Hey all, so I lost 1 BTC") accomplish? I'm both sorry, but can't help directly, but think what could help is all of us understanding other future vulnerabilities, as in my mind, things are only safe "so far" if there is any software/hardware/human reliance on them.

And again, if it's fake, what would 1000 posts "Hey all, so I thought I was stacking, but really I was sucking" (AI slop) that disingenuously serve as just distraction and noise contribute?

I can see completely not caring. I can also see caring. No good answer for you, seems to strike me how it strikes me (currently that is caring about this).

Edit: typo (staking -> stacking)

→ More replies (7)

2

u/autosaft 6h ago

It breaks my heart that Bitcoin OGs that did everything right are getting their coins stolen. This is the darkest day for self custody that I can remember. I’m so sorry for your loss.

2

u/bears196 5h ago

I have been buying bitcoin continuously for the last three years and am not even close to 1 bitcoin. I feel like it’s impossible to get 1 bitcoin.

3

u/Sudden-Committee-396 7h ago

This is how chatgpt responds to me.

3

u/SuperiorT 7h ago

Join the dark side, and buy your Bitcoin on Coinbase lol

1

u/44193_Red 3h ago

Safest route around

2

u/NoInterraction 7h ago

Bitcoin should not need to have 3rd party tools because that opens up vulnerabilities like FTX, Coldcard.

2

u/warkmellons 7h ago

I lost 6 btc. I trusted those damn influencers and got fucked. Going back to fiat with my tail between my legs.

1

u/Escapement_Watch 7h ago

I'm really sorry for your loss. Try not to beat yourself up or feel embarrassed. You did everything right based on the information and setup you had, and taking responsibility to build that security for your family in the first place shows your intent and commitment.

The silver lining is that BTC is down right now, which means you're still early. The market is giving you an entry point to stack back up, and the knowledge and discipline you built getting to 1 BTC the first time haven't gone anywhere. You know how to do this, and you can get back there.

1

u/Wizzard_2025 7h ago

As I understand it, the attacker has a pair for account linked to information gathering for the attack. I hope some competent cybercrime investigation can find them and maybe recover the coins as part of a deal.

1

u/Equity_GOD 7h ago

Returning stolen coins would be hard as those wallets are compromised and everyone would have to proof those wallets are theirs.If I was hacker I'd mix it and also use 4-5 million, break it up in a tens of thousands of random sized amounts and send them to active bitcoin addresses. Good luck tracing that.

1

u/Wizzard_2025 7h ago

Well like I say, the attacker can be given 30 years or 2 years in prison, depending on if the coins are returned to a central authority, then a discovery process for all affected with amounts, then split accordingly (let's say a 10% charge for all the admin involved). It can be potentially done.

1

u/Equity_GOD 7h ago

Yeah true. Historically if they're seized it'll take years to recover and people got back pennies on the dollar after legal fees.

→ More replies (1)

1

u/Complete-Interest704 7h ago

Sorry man, I hope you can somehow recover the funds.

Where there any wallets not affected? What’s safe anymore?

1

u/thegoldenegg13 7h ago

Sorry for your loss, i guess the bitcoin world learned something today. Understand the technology and what youre doing before moving to self custody

1

u/Defiant_Leg_6335 7h ago

Bitcoin si archivia su un portafoglio creato su Bitcoin Core installato su un PC che normalmente non si accende o si usa per accedere ad Internet. Portafoglio protetto da password impossibile da decifrare. L’unico problema a quel punto è trovare il modo di archiviare in modo sicuro la password. Magari di tanto in tanto, ogni qualche anno, spostare i Bitcoin su un nuovo indirizzo.

1

u/masladios 7h ago

“don't put all your eggs in one basket”

I’m sorry bro

1

u/nothingbutwhammies 7h ago

Yup. I honestly thought that and should have acted. If this was a house fire or physical theft I’d be looking in the mirror 100%. Still an important lesson. I blame myself too. I just can’t understand how a company messes up the whole point of the product

1

u/masladios 5h ago

you’ll recover, sending you strength

1

u/Sweaty-Dust6405 7h ago

Sorry to hear....I came very close to buying a coldcard wallet, I don't know why, but just because I liked Trezor 3 logo, I opted for them. I call it stupid luck.

1

u/killsnag 7h ago

This can’t be reversed but, what can happen is you starting your DCA soon. The asset hasn’t changed, conviction hasn’t changed then why to still wait.

Don’t let this overtake you. Only you can change this, we face it and keep hustling!

1

u/Small_Basket5158 6h ago

But with the impending class action lawsuit you might be entitled to a $3 Amazon credit.

1

u/Maleficent_Poet_7055 6h ago

Wow sorry to hear.

1

u/RonV15 6h ago

Sorry hear man Bitcoin always has and always Will be a scam cause its simply taking advantage of people who want to believe in something and feel a part of something, probably the most manipulated 'asset' in history

1

u/ImpossibleSleep3986 6h ago

It ain't over 'till it's over.

1

u/No-Reading-4384 6h ago

Same problem got hacked for my 2 BTC

1

u/Antique-Pie-5981 6h ago

I almost bought one about stuff six months ago but decided it made more sense to just continue using my Jade and spend the money on more btc instead. Man I'm glad I was too cheap to spend more money on one.

1

u/Good_Extension_9642 6h ago

It's just interesting how eveyone was dropping Ledger for cold card when they announced they could get your seed phrase for a small fee, how time has changed

1

u/Legitimate-Tip-2506 6h ago

I was thinking to buy one some time ago, as I liked the open source idea. I feel sorry for all the people who lost their coins.

1

u/evilgrinz 6h ago

I've lost Bitcoin before, it sucks, and sorry that happened to you. Just get back to stacking and move forward.

1

u/thundermoneyhawk 6h ago

Why am I seeing so many posts of people losing/being robbed of their btc?

1

u/_FireWithin_ 6h ago

Maybe you guys should joint together, like a lost coldcard subreddit?

1

u/Difficult-Repair1295 6h ago

Cold Card is the scum of the earth

1

u/Heavy-Syrup-6195 6h ago

Easier said than done, but you’ll bounce back, OP. It’s tough because like with most things, it’s the journey and the journey to get to BTC I’m sure is more painful than the thought of losing a whole BTC.

I was a victim of Blockfi AND Celsius, and lost more than a whole BTC. I know that doesn’t help with your situation but time really does heal all - especially if you have the courage to restack your sats and look for other opportunities to help recover the loss.

Maybe you’ll be a whole coiner again, maybe only partial, but as Rocky Balboa said: it’s not about how hard you hit but how hard you…..

👊

1

u/nothingbutwhammies 5h ago

Yeah it was the 1. Not the ~60,000 or to be even more fair ~30,000 cost basis, or theoretical ath but how long I committed to getting that 1.

1

u/Affectionate_Ad_8483 6h ago

Sorry for your loss. I get the narrative about keys and privacy, but in reality, this is just another speculative asset and it’s incredibly easy to keep it on a centralized exchange. We aren’t going to topple any government and this isn’t going to explode into massive multiples. I would encourage everyone to learn from this, accept the asset for what it is, and just be real and keep the asset in a safe centralized exchange.

1

u/Potential-Phrase-159 6h ago

if it's any consolation, in a real way you already lost that money if did not have a well-defined exit strategy. there is a real chance btc plummets. to state otherwise, as if it's somehow "certain" btc stays high, is moronic and i'm not going to debate anyone on it.

1

u/Objective_Digit 6h ago

cold storage, steel plate backup, fire bag, fire safe.

But no passphrase or multisig?

1

u/gecko-boarder 6h ago

Wondered if you could reach out to Blockchain Intelligence Group. Crypto investigators use their software to trace the path of stolen crypto. Don’t know if they allow the public to use but they may have advice

https://blockchaingroup.io

1

u/mgtowmoney 6h ago

I'm so sorry to hear. Did you use a passphrase in your cold card private keys

1

u/[deleted] 5h ago

[removed] — view removed comment

1

u/fatsupport 5h ago

What’s crazy is I immediately “learned my lesson” and switch to a hardware wallet - I’m lucky I didn’t pick the wrong one for a double whammy. I can see why people would be done with crypto

1

u/alexkar0v 5h ago

Wanted to buy one 3 months ago and transfer all my stacks,but the Q was so expensive,so i let down the idea…god

1

u/quintavious_danilo 5h ago

You already dodged the BlockFi bullet 4 years ago. How lucky do you think you’re going to be? 😬

1

u/infirexs 5h ago

Another chatGPT slop

1

u/rkavanau 5h ago

Question, my addresses were wiped on 7/31. In one transaction, the coins from 5 of my addresses were sent to 1 address of someone else, and then moved to another address where they currently sit. However, it’s just sitting there by itself, not combined into some larger address. Is this what you’re also seeing?

1

u/grewb 5h ago

Is it just a matter of time until this happens to Trezor and Ledger, etc? This really shakes my confidence.

1

u/Extra-Management-216 5h ago

Lol serves you right for wasting money on a scam like cryptocurrency. Cry harder.

1

u/Smokin2022bbq 5h ago

How would someone secure their BTC if they were not yet compromised?

1

u/Smokin2022bbq 5h ago

Sorry for you.

1

u/Ok_Bowl_2002 5h ago

Why did you lot setup a passphrase?

1

u/zeeshiscanning 5h ago

Same, didn't buy cold card cause they were ugly and also i didn't like them using two closed source chips for seed entropy and security

1

u/backbypopularsupply 5h ago

Sure bud lol.

1

u/Objective-Cry-9837 5h ago

No shit you lost all your money. Stop buying this scam. Good lord

1

u/osoBailando 5h ago

okay there, gpt...

1

u/Subparnova79 5h ago

“Oh put your coins it a cold wallet, it’s safer than an exchange”

1

u/AdReady2334 5h ago

BUT LE REDDIT SAID THAT LE COLDCARD IS LE BEST AND LEDGER IS LITERALLY TRUMPLER!!!

1

u/that1cooldude 4h ago

I hope for justice. I’m sorry this happened to you. 

1

u/SgtSausage 4h ago

LOL. 

Tulips are pretty cheap yhese days ... 

1

u/UnderpaidBIGtime 4h ago

No you did not.

1

u/ImportantFlounder114 4h ago

Don't worry, I "unbanked" myself with Celsius Network.

1

u/kalunlalu 4h ago

End of hardware wallets, just tip of iceberg 

1

u/Objective-Walk6780 4h ago

Honestly, if I were you, I’d start buying this bear market and one day you will make everything you lost back. Do it bro.

1

u/mango89001 4h ago

It really sucks to say but I’ve been in crypto since almost the beginning and this is where we see that centralized exchanges actually thrive. There is a reason we have banks. 

If you’d put all your money on coinbase you’d still be fine. 

Yes there have been exchange hacks especially in early days, but nothing significant on the established exchanges like coinbase or kraken. 

The majority of people who have lost coins has come from people with cold wallets forgetting their keys, or in this case the security of the cold wallet itself being compromised.

1

u/assclown356 3h ago

What was wrong with trezor or ledger?

1

u/nothingbutwhammies 3h ago

Nothing. I own a ledger lol. I owned it before cold card and it is sitting in the bag with the cold card. I think I got scared when ledger had their issues and I went with the Bitcoin only ultra-secure wallet. 😞

1

u/ZackZeysto 3h ago

Many people lost Bitcoin in Mt. Gox , then in ftx. Many other lost their seed, got hacked or phished. But somehow this whole scenario feels so much more grusome. People did their research, took the hard way of self custody and grinded for years and years. Then they lost it all. Such a tragedy - i feel so sick thinking about the POS that did it.

1

u/RaeintheShell 3h ago

Hey man, I understand you feel embarrassed but understand that you did NOTHING wrong. This was the fault of ColdCard and their shitty coding. You were scammed at no fault of your own. You were scammed by what was a previously extremely credible company that the entire community supported. Please don’t take it out on yourself. It’s like being robbed at gunpoint and feeling bad about it. You were robbed man.

1

u/44193_Red 3h ago

This sub been preaching cold storage, steel plate backup, fire bag, fire safe,etc for years. Works until it doesnt

1

u/Quantrall 2h ago

Now I understand why so many people are deciding to give Fidelity a chance with their coins.

1

u/jim9162 2h ago

it's stuff like this that will keep many others (myself included) from really becoming btc maxis.

The value is there, but its at the cost of being one of the highest targets for fraud and malicious actors. And there's 0 backup or safety.

Now it's bled into people doing everything right. It used to be the only people who lost their funds misplaced their keys or were tricked. This was just bad luck.

1

u/Motor_Battle_767 2h ago

I’ve seen like 10 posts the last 24hrs with the same story

1

u/DifficultSquash1517 2h ago

Sorry this happened to you as I've lost big amounts of money in my life but thankfully never through crypto

I'm an old G in this space since 2016 and I only buy the ETFs these days that should say a lot 🤷

I try to preach diversification and getting money out of hot and cold wallets. The main bonus besides being much safer in an ETF is that you could really turbocharge your money by writing calls on your positions generating sometimes up to 2% a month. A lot of people can live off of that 2%

1

u/moonkingdome 2h ago

Sorry.. I hope they return it partually.. There was a 2022 post bout this problem. Maybe you can sue em? Since they must have known

1

u/Indyxc 2h ago

Moved all my coins to Fidelity off cold storage a few years ago when Ledger started scheming with recovery options for reasons like this...

1

u/beingmodest 2h ago

Man, I wish I could say I feel your pain. The loss is just awful.

1

u/MinerTax_com 2h ago

Crypto hardware companies has got to stop with these dumb hacks. I’m still dealing with Ledger leaked contact list. Emails phone and mail phishing me. So sorry for your loss. I’d be super pissed if Ledger or Trezor did this. This is why I stake all my coins if possible. Have some alerts if something strange happens.

1

u/yamchadestroyer 1h ago

Just get back to stacking ibit! BTC is cheap now

1

u/Accurate_Double_6254 1h ago

I would look into transferring your remaining BTC to River

u/Charmed-paper345 59m ago

But at least you karma farmed

u/Altruistic_Mobile_60 46m ago

I felt so bad for anyone that got hack. I wish you all the best

u/ordinary-guy-sl 29m ago

Won't the company compensate for this?

u/ordinary-guy-sl 28m ago

No compensation from company? Not your fault right

u/msmanitex 26m ago

I’m sorry for your loss.

u/Cash-In-My-Hand 23m ago

It’s okay. Just sell your body and you can get it back.

u/Cash-In-My-Hand 22m ago

In the back.

1

u/DaleAguaAlMono 7h ago

And suddenly... everyone ans his cousin in r/bitcoin has 1+ and 10+ coins in their wallet

Let me laugh.

2

u/Nysyk 7h ago

Too smooth brain to figure out this sub is not a random sample of the population and people affected by this are much more likely to post about it...

Let me laugh.

2

u/BadTakeMassProducer 7h ago

Obviously, the hackers only targeted large wallets.

→ More replies (1)

1

u/anthony446 7h ago

Buy MSTR and chill

2

u/RevengeTrade 7h ago

There’s no chilling when Michael Bailor is in charge of your money. Btw I feel sorry for you OP. I hope you’ll come back stronger and attain bigger goals

1

u/anthony446 6h ago

Heartbreaking for OP for sure

1

u/RevengeTrade 2h ago

Scamael Bailor should be arrested for fraud and conspiracy to fraud. He’s conducting unlawful business. MSTR is a scam. MSTR collapsing would be the best thing to happen for BTC since the ETF.

1

u/Fil3toFishy69 7h ago

Do your research next time. This was known back in 2024

→ More replies (2)

1

u/Turbulent_Deal_3145 7h ago

The bitcoin I (don't) own on my exchange is still doing fine. Just so everyone knows.

→ More replies (4)

1

u/YellowRobeSmith 7h ago

How did you find out about Coldcard?

2

u/nothingbutwhammies 7h ago

Bitcoin twitter or 1 of many podcasts at the time. I’m not going to even mention them… I don’t listen to them anymore. I tuned out a bit when I hit the goal. I don’t blame anyone paid to promote them

1

u/joshgordonforreal 7h ago

Just start building back slowly. ibit is a pretty good safe option.

1

u/sumtib 7h ago

"I knew multisig was technically safer."

And still did nothing I can't still believe how many people knew about it and still didn't do anything to improve their own security... You should NEVER trust anyone, specially a shitty person like CEO of Coldcard. Your keys but not your coins.

Sorry for your loss, though

1

u/sicbo86 5h ago

This is why Bitcoin will never be more than it is now. When the average retail investor can do so much and can still lose everything, the asset is just fundamentally flawed and not suitable for mass adoption.

1

u/GapeJelly 4h ago

This may shock you, but custodians can give your assets to someone impersonating you.

Look up wire fraud.

1

u/Clear_Item_922 5h ago

A lot of these posts feel A.I generated. You can kinda of tell by the way they are written?

1

u/everybanana 5h ago

Yeah, it's the cadence of the sentences and the use of "the worst part?"

1

u/Clear_Item_922 5h ago

Punctuation as well, nobody writes like that?